Manually upload files to Intelligent Sandbox for analysis.
Make sure that the required analyzer profile is available with the Enable Malware Internet Access option selected.
To completely execute some malware, user intervention might be required.
For example, a default setting in the analyzer VM might pause the execution unless the setting is manually overridden. Some files might display dialog boxes, where you are required to make a selection or a confirmation. Malware demonstrates such behavior to determine if they are being executed in a sandbox. The behavior of the malware might vary based on your intervention. When you submit files in user-interactive mode, the analyzer VM opens in a pop-up window on your client computer and you can provide your input when prompted.
You can upload files to be executed in the user-interactive mode. This option is available only when you manually upload a file using the Intelligent Sandbox web interface. For files submitted by other methods, such as FTP upload and files submitted by Network Security Platform, requests for user intervention by the malware are not honored. However, the screen shots of all such requirements are available in the Screenshots section of the Analysis Summary report. Then you can manually resubmit such files in the user-interactive mode to know the actual behavior of the file.
Note
For XMode, Google Chrome version ranges from 44.0.2403 - 107.0.5304.107, Mozilla Firefox version 40.0.3 - 105.0.2, Microsoft Edge version 79 - 107.0.1418.42 for Windows 10 and 11, Microsoft Edge 104.0.1290.91 and later for Windows Server 2019 are supported. XMode does not support Microsoft Internet Explorer.
Note
Because the analyzer VM is opened in a pop-up window, make sure the pop-up blocker is disabled in your browser.
Log on the Intelligent Sandbox web interface.
Click → → , then locate and open the file you want to submit for analysis.
You can also drag and drop the file on the Drop your file here box.
If you are uploading a password-protected .zip file, make sure you have provided the password in the analyzer profile that you want to use for analysis.
If dynamic analysis is required, the files in the .zip file are executed on different instances of the analyzer VM. If enough analyzer VMs are not available, some of the files are in the pipeline until analyzer VMs are available.
Because the files in the .zip file are analyzed separately, separate reports are created for each file.
Unicode is supported for the file name of samples. A file names can contain non-English characters and special characters.
Note
File names are displayed as the MD5 hash value of the file if the following characters are used: "'`<>|;*?#$*
The file name can be up to 200 bytes in length.
From the Analyzer Profile drop-down list, select the analyzer profile.
From the Submission Priority drop-down list, select the priority.
Select one of these options, then click Submit
User Interactive Mode (XMode)
On the Uploaded File Successfully window, click OK, then click OK on the pop-up message. On the Analysis Status page, locate the sample and click X-Mode.
When the file execution completes, the VM automatically shuts down and you are unable to use Connect to view the VNC session. When you click Disconnect, Intelligent Sandbox closes the VNC session from the client and displays the VNC disconnected message.
Enabling X-Mode overrides the maximum execution time in the Analyzer profile to the X-Mode time.
Skip files if previously analyzed.
Intelligent Sandbox is unable to skip sample analysis in these scenarios:
Analyzer profile settings change after the last analysis
The last submitted sample analysis occurred three days prior
You used URL Download to submit the samples
Note
When you submit a previously analyzed .zip file, Intelligent Sandbox displays the sample with the highest severity.
Note
Password protected PDF files will be analyzed only in X-Mode, where user can provide the password. In non X-Mode, the sample will have its severity marked as Failed with the message
Pre-filter heuristics determined that this file is encrypted and therefore cannot be analyzed.